🇩🇪
Vegascosmetics
2026-08-30 21:51:42
(8 minutes ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-08-30 21:43:56
(16 minutes ago)
cloudlinux2 fail2ban: 2026-08-30 23:38:50,886 fail2ban.filter [1459]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-30 23:38:50,886 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 104.234.53.204 - 2026-08-30 23:38:50cloudlinux2 fail2ban: 2026-08-30 23:39:01,595 fail2ban.actions [1459]: NOTICE [plesk-wordpress] Ban 104.234.53.204cloudlinux2 fail2ban: 2026-08-30 23:39:01,571 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 104.234.53.204 - 2026-08-30 23:39:00cloudlinux2 fail2ban: 2026-08-30 23:39:01,656 fail2ban.filter [1459]: INFO [recidive] Found 104.234.53.204 - 2026-08-30 23:39:01cloudlinux2 fail2ban: 2026-08-30 23:38:57,041 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 34.45.53.155 - 2026-08-30 23:38:57cloudlinux2 fail2ban: 2026-08-30 23:38:57,685 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 104.234.53.204 - 2026-08-30 23:38:57cloudlinux2 fail2ban: 2026-08-30 23:39:18,153 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 63.135.161.33 - 2026-08-30 23:39:17cloudlinux2 fail2ban: 2026-08-30 2
show less
Web App Attack
Anonymous
2026-08-30 21:23:26
(37 minutes ago)
34.45.53.155 - - [30/Aug/2026:21:23:25 +0000] "GET /.git/config HTTP/1.1" 404 7771 "-" "-"
...
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-30 21:22:48
(37 minutes ago)
[Mon Aug 31 07:22:48.125206 2026] [security2:error] [pid 1203] [client 34.45.53.155:36822] [client 3 ...
show more
[Mon Aug 31 07:22:48.125206 2026] [security2:error] [pid 1203] [client 34.45.53.155:36822] [client 34.45.53.155] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/.git/config"] [unique_id "apSfKC1dwwisRS5czBfwOgAAAAQ"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 21:12:38
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:12:30.846688 2026] [security2:error] [pid 8894:tid 8894] [client 34.45.53.155:33294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matterofbritain.com"] [uri "/.git/config"] [unique_id "apScvskWz8Mrm3RPvrtjUwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
oisecnet
2026-08-30 21:02:31
(57 minutes ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-08-30. 1186 requests from thi ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-08-30. 1186 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:53:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:52:56.878201 2026] [security2:error] [pid 26900:tid 26900] [client 34.45.53.155:49388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.truecontrarian.com"] [uri "/.git/config"] [unique_id "apSYKK6zItQHD8PyRRLvtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-30 20:41:55
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-08-30 20:41 UTC
show less
Hacking
Web App Attack
🇺🇸
johnkarlhill
2026-08-30 20:30:03
(1 hour ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
🇦🇺
2000cn.com.au
2026-08-30 20:23:58
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
cwytech
2026-08-30 19:58:04
(2 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:54:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:54:03.065226 2026] [security2:error] [pid 8467:tid 8467] [client 34.45.53.155:44558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indieheaven.io"] [uri "/.git/config"] [unique_id "apSKW9lX6mHeI7KsO7kfbgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-08-30 19:41:56
(2 hours ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 19:24:42
(2 hours ago)
apache vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:17:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.53.155 (155.53.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:17:45.145491 2026] [security2:error] [pid 25872:tid 25872] [client 34.45.53.155:34264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stantontownship.org"] [uri "/.git/config"] [unique_id "apSB2cmaQ71UGRrU_F09gAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack